A current transformer on a tenant's supply measures amps. Whether that measurement is personal data depends on the records around it, not on the sensor. If a sub-meter register says that one ZEM-65 monitors the supply to Flat 2B, and a lease says who lives in Flat 2B, then every reading from that meter is personal data about that person.
This guide covers the EU GDPR. UK sites are under the UK GDPR and the Data Protection Act 2018. The provisions cited here have direct equivalents in the UK text, but check the UK wording where the Data (Use and Access) Act 2025 amended it.
When energy data is personal data
Article 4(1) defines personal data as information about an identified or identifiable natural person. A person is identifiable if you can single them out directly or indirectly, including by an identification number. Recital 26 limits this to means "reasonably likely to be used", by you or by another person.
Use this test on each channel. Can any record that you or a party you share data with holds link the channel to a living person? Typical linking records are a lease, a sub-meter register, a desk or room booking system, an HR record and an account number. If the answer is yes, the channel is personal data. It stays personal data if you replace the names with codes and keep the code list, because pseudonymised data is still personal data (Recital 26).
Three cases occur often:
- A dwelling, a sole trader's unit or a single-occupant office. The channel is personal data. The Article 29 Working Party reached this conclusion for smart meters in Opinion 12/2011, because the meter identifier is linked to the account holder.
- A limited company tenant. Data about a legal person is not personal data (Recital 14). A 400-person company's floor supply does not identify an employee.
- A sub-circuit that covers one person's workspace, such as a desk socket circuit, a single office's heater or a lab bench with one assigned user. This is employee data, even inside a company tenancy.
Sample interval and what it reveals
Sample interval does not decide whether data is personal data. It decides how much the data shows about a person, and so it changes the balancing test, the DPIA and the minimisation argument.
Daily totals from a dwelling show whether someone was home. Half-hourly data shows when they got up, left and came back. At one sample per second or faster, individual appliances appear as step changes in power: a 2 to 3 kW kettle, an 8 to 10 kW electric shower, an oven cycling its element. This is the basis of non-intrusive load monitoring (NILM), which infers appliance use from a single supply measurement.
Opinion 12/2011 recommends two design rules. Transmit readings only as often as the system or the agreed service needs. Keep data within the household network unless it must go elsewhere. On an energy monitoring system, the equivalent is this: set the reporting interval for the purpose, and keep fine-grained data on site.
Worked example: a multi-tenant office building
A landlord monitors a four-storey building. Each floor has a distribution board with a ZEM-65 on the incomer. Floors 1 to 3 are let to limited companies. Floor 4 is split into six serviced offices, each on its own monitored sub-circuit, and three of those are let to sole traders. The purpose is to find base-load waste and to recharge tenants for their electricity.
The floor 1 to 3 incomers carry company data and are not personal data. The six floor 4 sub-circuits are personal data for the three sole traders, and for any single-occupant room where the landlord knows who sits there.
The design that follows from this:
- Record all channels in local history on the Gateway, at the interval needed for base-load analysis.
- Create a calculated device in Edge that sums the six floor 4 sub-circuits. Enable export on the total. Disable export on the six individual channels.
- Export the four floor totals to the landlord's energy platform over MQTTS.
- Produce each sole trader's recharge from the local history once a month, as a kWh figure per billing period. That is the contract data the lease needs. Set local retention longer than the billing period, for example 45 days. At the 30-day default, the first day of a 31-day month has expired before you run the recharge.
A failure mode to check: a total can leak an individual value. If you export the floor 4 total and also export five of the six sub-circuits, anyone can subtract to get the sixth. The same applies when a floor has one occupied room. Review the export set as a whole, not channel by channel.
Controller and processor
The controller decides why and how the data is processed (Article 4(7)). The processor processes it on the controller's behalf (Article 4(8)). In the example above, the landlord is the controller.
- An installer or managing agent that commissions the Gateway and runs the system for the landlord is a processor.
- A hosted energy platform that receives the exported data is a processor. It needs a data processing agreement under Article 28.
- An energy services company or aggregator that uses the data for its own purposes, such as its own flexibility trading, is a controller for that use. It needs its own lawful basis.
- Edge runs on the Gateway on the site's network. Unless you configure an export destination or a backup, measurements do not leave the site, and no supplier processes them. A supplier, including EpiSensor, that gets remote support access to the Gateway or hosts a service that receives the data is a processor for that activity. Put that access in the processor agreement.
Lawful basis
For commercial sub-metering, the usual basis is legitimate interests, Article 6(1)(f). Record a legitimate interests assessment in three parts: the purpose (for example cost recovery and base-load reduction), necessity (why this data at this interval, and why the floor total is not sufficient), and the balance against the person's reasonable expectations. Public authorities cannot use legitimate interests for processing in the performance of their tasks (Article 6(1), final subparagraph). They use public task, Article 6(1)(e).
Contract, Article 6(1)(b), covers the recharge figure a lease requires. It does not cover finer data than the contract needs. Opinion 12/2011 makes the same point for billing: a quarterly bill does not make continuous readings necessary.
Consent is a poor fit. It must be freely given and the person can withdraw it at any time (Article 7(3)). A withdrawal means you must stop processing that channel. Recital 43 and EDPB Guidelines 05/2020 say that consent is rarely valid where there is a clear imbalance of power, which includes employer and employee. A tenant who must accept a monitoring clause to get the lease is in a similar position.
Legal obligation, Article 6(1)(c), is not a general basis for sub-metering. Article 11 of the Energy Efficiency Directive (EU) 2023/1791 requires an energy management system for enterprises above 85 TJ average annual consumption, and an energy audit above 10 TJ. That obligation concerns the enterprise's energy use. It does not require data about individual occupants, so it does not support occupant-level processing.
Employee monitoring and the DPIA
Sensors that cover workstations, single offices or assigned equipment monitor employees. Article 88 lets member states set more specific rules for employment data, and several states give works councils a say before an employer introduces technical monitoring. Check national law before you commission this kind of channel.
Article 35 requires a DPIA where processing is likely to result in a high risk. The WP 248 guidelines list nine criteria and say that processing which meets two of them usually needs a DPIA. Occupant-level energy monitoring often meets three: systematic monitoring, vulnerable data subjects (employees are named as an example because of the power imbalance) and matching of datasets (meter data joined to a lease or HR record). Do the DPIA before installation. It is much cheaper to remove a sub-circuit from the design than from a running system.
Data minimisation on the Gateway
Article 25 requires data protection by design and by default. Article 25(2) applies "by default" to four things: the amount of data collected, the extent of processing, the storage period and accessibility. EDPB Guidelines 4/2019 explain how to apply each one. On an EpiSensor Gateway, these are Edge settings, not policy statements.
- Reporting interval. Set each device's reporting interval for its purpose. Base-load analysis on a floor incomer works at 1 to 5 minutes. Do not collect 1 s data on an occupant's circuit unless the purpose needs it.
- Local history. In Settings > Data, choose which measurements Edge records. An unrecorded measurement cannot be exposed later.
- Export selection. Export is a separate choice for each sensor. Edge filters out measurements with export disabled before they reach any external destination.
- Local aggregation. Calculated devices sum channels on the Gateway. Export the total and keep the inputs local.
- Identifiers. The native Edge JSON export identifies each point by Gateway ID, device serial number and export ID. It carries no tenant name unless you put one in a device name or export ID. Keep names out of both, and hold the mapping from serial number and channel to unit in one controlled register.
- Access. Give each person a named Edge account with the minimum role, for example Viewer for a facilities team that reads dashboards.
- Transport. Send exported data over MQTTS or HTTPS with certificate validation. See the MQTT over TLS guide for broker identity and topic access.
Retention and erasure
Article 5(1)(e) requires that you keep identifiable data no longer than the purpose needs. Derive the period from the purpose and write the reason down. For example, keep monthly recharge figures for as long as the lease requires for billing disputes. Keep interval data for measurement and verification for the baseline and reporting periods in the M&V plan. Do not choose a round number and justify it afterwards.
Edge keeps local history for 30 days by default. An administrator can change the period through the configuration command, and the change takes effect after a full Edge restart. When you reduce the period, Edge expires the older history. You cannot recover it.
Three copies are outside that retention period, and each is a common failure:
- The retry queue. When a destination is unavailable, Edge queues export data for replay. Pending replay has no age limit. After a long outage, the queue can hold data older than the local history period. Monitor the queue and restore the destination.
- Backups. An automatic backup with the "All Edge data" scope includes a snapshot of telemetry history. It goes to the S3-compatible store you configure, with its own retention. Check where the bucket is and how long it keeps objects.
- Downstream platforms. The receiving platform has its own retention. Set it in the processor agreement.
For an erasure request (Article 17), the practical method on a time series is to delete the identifying link and the identifying data together. Remove the channel's entry from the mapping register. Delete or let expire the channel's history in each store above. Aggregates that you calculated earlier, such as a floor total, can stay if they do not identify the person without the deleted inputs. Article 17(3) exceptions, such as retention for a legal claim about a disputed recharge, can justify keeping specific records.
Data subject rights
Answer a request within one month. You can extend this by two further months for complex or numerous requests (Article 12(3)). The rights that apply depend on the lawful basis:
- Access (Article 15) applies in every case. Export the channel's history and the recharge records for the person's unit.
- Portability (Article 20) applies only when the basis is consent or contract and the processing is automated. It does not apply to processing under legitimate interests.
- Objection (Article 21) applies to processing under legitimate interests or public task. You must stop unless you show compelling legitimate grounds. For direct marketing, the right is absolute.
Processor agreements and breach notification
Article 28(3) lists what a processor agreement must contain: the subject matter, duration, nature and purpose, the data types and categories of data subjects, documented instructions, confidentiality, security measures, sub-processor terms, assistance with rights requests and breaches, deletion or return at the end, and audit rights.
Breach notification has two separate deadlines. A processor must notify the controller without undue delay after it becomes aware of a breach (Article 33(2)). Agree a fixed window in the contract, such as 24 or 48 hours. The controller must notify the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people (Article 33(1)).
Transfers outside the EEA
A transfer happens when personal data goes to a recipient outside the EEA. This includes a cloud platform, a backup bucket and a remote support team. The GDPR permits transfers under an adequacy decision (Article 45) or appropriate safeguards (Article 46).
For US recipients, the EU-US Data Privacy Framework adequacy decision (EU) 2023/1795 has applied since 10 July 2023, but only to organisations that are certified under the framework. For other recipients, use the 2021 Standard Contractual Clauses with a transfer impact assessment. EDPB Recommendations 01/2020 describe the supplementary measures when that assessment shows a gap. The simplest control is architectural: when fine-grained data stays on the Gateway and only floor totals leave the site, the data you transfer is not personal data.
Before go-live
- Make a list of every channel that one person's circuit, room or unit supplies. Keep it with the mapping register.
- Record the lawful basis and the legitimate interests assessment for those channels.
- Do a DPIA if the system meets two or more WP 248 criteria.
- Set the reporting interval, local history and export selection for each channel. Check the export set for subtraction leaks.
- Record retention for local history, the retry queue, backups and each downstream platform.
- Sign Article 28 agreements with every processor. Include remote support access.
- Confirm where each destination and backup bucket is, and the transfer mechanism for each one outside the EEA.